Staff Security Engineer

Okta Okta · Enterprise · Toronto, ON · Sec - Corp Security-186

Staff Security Engineer at Okta responsible for strengthening security posture by performing security assessments of third-party integrations and connected apps, with a focus on mitigating API-related security risks. The role involves operationalizing AI for Security use cases to automate and scale security operations, analyzing API permissions, developing security review workflows, and identifying/mitigating vulnerabilities. The candidate should have deep technical expertise in information security, API security, and practical threat modeling, with experience in security platforms and an interest in applying AI to security tasks.

What you'd actually do

  1. Lead Technical Security Reviews: Perform in-depth security reviews and threat modeling for complex enterprise applications and third-party integrations.
  2. Operationalize AI for Security: Take the lead in deploying and managing AI for Security use cases, such as integration security reviews, to automate and scale security operations.
  3. Risk Analysis & Documentation: Analyze and document API permissions and risk levels for major integrations (e.g., Salesforce, Slack, Google) to ensure they meet internal standards.
  4. Develop Workflow Processes: Collaborate with stakeholders to design and implement repeatable security review workflows, such as the Salesforce API Integration Review.
  5. Vulnerability & Control Gap Mitigation: Identify potential vulnerabilities and security control gaps in connected apps and recommend technical mitigation strategies to stakeholders.

Skills

Required

  • information security
  • application security
  • enterprise security
  • API security
  • threat modeling
  • secure-by-design principles
  • least privilege model
  • security platforms for analyzing application permissions
  • communication skills

Nice to have

  • interest or background in applying AI to streamline security tasks

What the JD emphasized

  • mitigating API-related security risks
  • operationalize AI for Security
  • applying AI to streamline security tasks

Other signals

  • deploying and managing AI for Security use cases
  • automate and scale security operations
  • applying AI to streamline security tasks